{"items":[{"id":"d36262dc6684","title":"Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild","link":"https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html","summary":"A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote…","publishedAt":"2026-09-19T08:18:54.000Z","source":{"id":"thehackernews","name":"The Hacker News","site":"https://thehackernews.com","category":"News"},"priority":78,"severity":"critical","tags":["Exploited in the Wild","Unauthenticated","RCE","Critical","Vulnerability"],"cves":["CVE-2026-58138"]},{"id":"c8019563e962","title":"SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE","link":"https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html","summary":"SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is…","publishedAt":"2026-09-19T09:31:17.000Z","source":{"id":"thehackernews","name":"The Hacker News","site":"https://thehackernews.com","category":"News"},"priority":70,"severity":"critical","tags":["Unauthenticated","RCE","Vulnerability"],"cves":["CVE-2026-28326"]},{"id":"9de6b003d2fd","title":"CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild","link":"https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below…","publishedAt":"2026-09-19T06:24:10.000Z","source":{"id":"thehackernews","name":"The Hacker News","site":"https://thehackernews.com","category":"News"},"priority":58,"severity":"high","tags":["Exploited in the Wild","Vulnerability"],"cves":[]},{"id":"c1d5bcc89f74","title":"ShinyHunters hacks Clop leak site, threatens to extort ransomware gang","link":"https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/","summary":"The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]","publishedAt":"2026-09-19T13:48:32.000Z","source":{"id":"bleepingcomputer","name":"BleepingComputer","site":"https://www.bleepingcomputer.com","category":"News"},"priority":49,"severity":"elevated","tags":["Ransomware"],"cves":[]},{"id":"a2e750d4734f","title":"AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum","link":"https://securityaffairs.com/199378/ai/ai-helps-hackers-hijack-openai-staff-accounts-through-a-forum.html","summary":"AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely…","publishedAt":"2026-09-19T13:01:08.000Z","source":{"id":"securityaffairs","name":"Security Affairs","site":"https://securityaffairs.com","category":"Geopolitical"},"priority":40,"severity":"elevated","tags":["Exploit","Vulnerability"],"cves":[]},{"id":"cc2fd48c518b","title":"Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws","link":"https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html","summary":"Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the…","publishedAt":"2026-09-19T18:36:53.000Z","source":{"id":"thehackernews","name":"The Hacker News","site":"https://thehackernews.com","category":"News"},"priority":39,"severity":"elevated","tags":["Vulnerability"],"cves":[]},{"id":"f8afd4069f09","title":"BragJack attacks hijack AI browser agents through malicious extensions","link":"https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/","summary":"BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties…","publishedAt":"2026-09-19T14:56:31.000Z","source":{"id":"bleepingcomputer","name":"BleepingComputer","site":"https://www.bleepingcomputer.com","category":"News"},"priority":38,"severity":"elevated","tags":["Exploit"],"cves":[]},{"id":"b2876269df9a","title":"Identity Visibility in 2026: The Foundation of Identity Security","link":"https://thehackernews.com/2026/09/identity-visibility-in-2026-foundation.html","summary":"Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This…","publishedAt":"2026-09-19T13:28:41.000Z","source":{"id":"thehackernews","name":"The Hacker News","site":"https://thehackernews.com","category":"News"},"priority":38,"severity":"elevated","tags":["Breach"],"cves":[]},{"id":"637954cda03c","title":"Google Gemini also Broke Out of Its Test Environment","link":"https://securityaffairs.com/199392/ai/google-gemini-also-broke-out-of-its-test-environment.html","summary":"Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into the systems of three real companies during a cybersecurity…","publishedAt":"2026-09-19T14:09:34.000Z","source":{"id":"securityaffairs","name":"Security Affairs","site":"https://securityaffairs.com","category":"Geopolitical"},"priority":37,"severity":"elevated","tags":["Breach"],"cves":[]},{"id":"f451f7682a61","title":"[Virtual Event] Cybersecurity Outlook 2027","link":"https://www.darkreading.com/events/virtual-event-cybersecurity-outlook-2027","summary":"","publishedAt":"2026-09-19T22:30:18.994Z","source":{"id":"darkreading","name":"Dark Reading","site":"https://www.darkreading.com","category":"News"},"priority":34,"severity":"informational","tags":[],"cves":[]},{"id":"cfe7f416ead5","title":"North Korean WaterPlum hackers infected 30,000 devices worldwide","link":"https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/","summary":"A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]","publishedAt":"2026-09-19T14:05:15.000Z","source":{"id":"bleepingcomputer","name":"BleepingComputer","site":"https://www.bleepingcomputer.com","category":"News"},"priority":33,"severity":"informational","tags":["Patch"],"cves":[]},{"id":"b7b0f8d9ba00","title":"TigerByte Cyber Emerges From Stealth With $3 Million in Funding","link":"https://www.securityweek.com/tigerbyte-cyber-emerges-from-stealth-with-3-million-in-funding/","summary":"The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.","publishedAt":"2026-09-19T14:30:00.000Z","source":{"id":"securityweek","name":"SecurityWeek","site":"https://www.securityweek.com","category":"News"},"priority":26,"severity":"informational","tags":[],"cves":[]},{"id":"7d7f9cff7d80","title":"Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar","link":"https://thehackernews.com/2026/09/can-you-prove-new-cve-is-exploitable.html","summary":"A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working…","publishedAt":"2026-09-19T13:28:48.000Z","source":{"id":"thehackernews","name":"The Hacker News","site":"https://thehackernews.com","category":"News"},"priority":25,"severity":"informational","tags":[],"cves":[]},{"id":"663f5a6aab61","title":"Agentic security is the billion-dollar challenge for some clever startup to solve","link":"https://www.theregister.com/security/2026/09/19/agentic-security-is-the-billion-dollar-challenge-for-some-clever-startup-to-solve/5297546","summary":"High time to stop kicking the security can down the road, investor tells The Reg","publishedAt":"2026-09-19T14:25:00.000Z","source":{"id":"theregister","name":"The Register · Security","site":"https://www.theregister.com/security","category":"News"},"priority":24,"severity":"informational","tags":[],"cves":[]},{"id":"f3c57bf9f56a","title":"Viral AI actress' hotline face-scans every caller, watches their mood","link":"https://www.bleepingcomputer.com/news/security/viral-ai-actress-hotline-face-scans-every-caller-watches-their-mood/","summary":"AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her \"Talking Tilly\" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on…","publishedAt":"2026-09-19T11:38:20.000Z","source":{"id":"bleepingcomputer","name":"BleepingComputer","site":"https://www.bleepingcomputer.com","category":"News"},"priority":24,"severity":"informational","tags":[],"cves":[]},{"id":"7c704cae3839","title":"HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)","link":"https://isc.sans.edu/diary/rss/33352","summary":"In June 2026 the IETF published RFC 10008[1], defining a new HTTP method: \"QUERY\". The HTTP protocol faced already by changes (HTTP/2, HTTP/3) but it's the first new standard HTTP verb since \"PATCH\" in 2010!","publishedAt":"2026-09-19T04:51:46.000Z","source":{"id":"isc-sans","name":"SANS Internet Storm Center","site":"https://isc.sans.edu","category":"Research / CERT"},"priority":24,"severity":"informational","tags":["Patch"],"cves":[]},{"id":"71746d073e50","title":"Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up","link":"https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html","summary":"Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in…","publishedAt":"2026-09-19T07:51:34.000Z","source":{"id":"thehackernews","name":"The Hacker News","site":"https://thehackernews.com","category":"News"},"priority":19,"severity":"informational","tags":[],"cves":[]},{"id":"bf0f679dfdf4","title":"CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories","link":"https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html","summary":"An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was…","publishedAt":"2026-09-19T07:14:54.000Z","source":{"id":"thehackernews","name":"The Hacker News","site":"https://thehackernews.com","category":"News"},"priority":18,"severity":"informational","tags":[],"cves":[]}],"brief":{"threatLevel":{"level":"High","tone":"high","score":65,"blurb":"2 critical and 1 high-severity threats active now."},"trendingCves":[{"id":"CVE-2026-58138","count":1},{"id":"CVE-2026-28326","count":1}],"trendingTags":[{"tag":"Exploited in the Wild","count":2},{"tag":"Unauthenticated","count":2},{"tag":"RCE","count":2},{"tag":"Exploit","count":2},{"tag":"Breach","count":2},{"tag":"Critical","count":1},{"tag":"Ransomware","count":1}],"geopolitical":[{"id":"637954cda03c","title":"Google Gemini also Broke Out of Its Test Environment","link":"https://securityaffairs.com/199392/ai/google-gemini-also-broke-out-of-its-test-environment.html","summary":"Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into the systems of three real companies during a cybersecurity…","publishedAt":"2026-09-19T14:09:34.000Z","source":{"id":"securityaffairs","name":"Security Affairs","site":"https://securityaffairs.com","category":"Geopolitical"},"priority":37,"severity":"elevated","tags":["Breach"],"cves":[]},{"id":"a2e750d4734f","title":"AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum","link":"https://securityaffairs.com/199378/ai/ai-helps-hackers-hijack-openai-staff-accounts-through-a-forum.html","summary":"AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely…","publishedAt":"2026-09-19T13:01:08.000Z","source":{"id":"securityaffairs","name":"Security Affairs","site":"https://securityaffairs.com","category":"Geopolitical"},"priority":40,"severity":"elevated","tags":["Exploit","Vulnerability"],"cves":[]}]},"stats":{"totalItems":18,"criticalCount":2,"highCount":1,"sourcesOnline":32,"sourcesTotal":32,"windowHours":24,"generatedAt":"2026-09-19T22:30:18.994Z","failedSources":[]}}